Unmanned aerial vehicle data encryption secure transmission system
By using the national secret algorithm and OTP technology in the drone data transmission system, the data is encrypted by generating temporary encryption keys, solving the problem of data leakage and control rights caused by unencrypted data transmission in traditional drone data transmission, and achieving high-security data transmission.
Patent Information
- Application Number
- CN202421988877.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-16
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2034-08-16
AI Technical Summary
Traditional drone data transmission methods are not encrypted, and there is a risk of data leakage and control rights being robbed.
A drone data encryption and secure transmission system was designed, using the national secret algorithm and OTP technology, and a temporary encryption key was generated through the session key generation unit to encrypt the data symmetrically to ensure the security of data transmission.
It effectively enhances the security of data, prevents data from being stolen or tampered, ensures the security of control, and is suitable for application scenarios with high security requirements.
Smart Images

Figure CN223024579U_ABST
Abstract
Description
Technical Field
[0001] The utility model relates to the technical field of UAV data transmission, in particular to a UAV data encryption and secure transmission system. Background Technique
[0002] The UAV data transmission link is used for data transmission between the UAV and the remote controller, the ground station or the ground image receiving terminal. The traditional transmission method usually only performs necessary encapsulation on the data, but does not include encryption. This unencrypted transmission method has the risks of data leakage and control right seizure. The following is a detailed description of the prior art and its defects:
[0003] The current situation of traditional UAV data transmission:
[0004] In the prior art, the data transmission link of the UAV usually adopts a direct data transparent transmission method. Taking PX4 / MavLink as an example, as a typical UAV flight control and control system, when using a traditional radio station for transmission, the radio station direct connection mode is adopted, and the data is serial port data transparent transmission. A same-frequency radio station can capture the data and use MavLink software for parsing. When using 4G or 5G for transmission, UDP is usually used to transparently transmit the MavLink data stream. Since MavLink includes not only telemetry information but also control commands sent from the ground (or the remote controller), the unencrypted transmission not only has the risk of data leakage but also the problem of control right seizure; the flight distance of a single UAV is also limited, and the flight distance and signal transmission distance are also limited.
[0005] In view of this, in order to study and improve the existing problems, a UAV data encryption and secure transmission system is provided. Content of the Utility Model
[0006] The purpose of the utility model is to solve the defects existing in the prior art, and a UAV data encryption and secure transmission system is proposed.
[0007] In order to achieve the above purpose, the utility model adopts the following technical scheme: a UAV data encryption and secure transmission system, including an operation UAV, a relay UAV, and a ground station; the ground station includes a first wireless communication unit; the relay UAV includes a second wireless communication unit and an information confirmation unit; the operation UAV includes a UAV communication unit, a camera communication unit, and an encryption management unit;
[0008] The first wireless communication unit is electrically connected to the ground station and communicates with the second wireless communication unit;
[0009] The second wireless communication unit is electrically connected to the relay UAV, communicates with the UAV communication unit, receives flight status data and sends control commands from the ground station. It also communicates with the camera communication unit, receives camera images and sends them to the ground station, and sends camera and gimbal control commands from the ground station.
[0010] The information confirmation unit is electrically connected to the second wireless communication unit, determines whether the received instructions from the ground station match, and determines whether the encrypted information of the received operation UAV is complete.
[0011] The UAV communication unit is electrically connected to the encryption management unit and communicates with the flight control unit of the operation UAV.
[0012] The camera communication unit is electrically connected to the encryption management unit and communicates with the camera of the operation UAV.
[0013] The encryption management unit is electrically connected to the operation UAV and is used for data encryption and decryption. It includes a session key generation unit. The encryption management unit also includes a national cryptographic algorithm encryption chip, an OTP algorithm unit, and a data encryption / decryption session management module.
[0014] The session key generation unit establishes a temporary encryption key between the two communication parties to ensure the security of data transmission. The generated session key will be used for symmetric encryption of the transmitted data. It includes a JOIN algorithm module, a HASH algorithm module, and an F algorithm module.
[0015] Optionally, the JOIN algorithm module is as follows: Obtain the system UNIX timestamp T1, the number of seconds calculated from January 1, 1970. Take the alignment result of 60, T = Treal−(Treal % 60), to obtain the time parameter T and convert it into the HEX character form. Generate a true random number RNG through the RNG unit in the encryption chip. Take the unique serial number S of the chip and the preset encryption password K. Concatenate T, RNG, S, and K in string form to form the JOIN result.
[0016] Optionally, the HASH algorithm module performs a hashing operation using the SM3 algorithm to generate a HASH result. The HASH algorithm module selects SHA192, SHA256, or SM3.
[0017] Optionally, the F algorithm module performs calculations, splitting, and recombination on the HASH result to generate a session key Skey that meets the length of the encryption algorithm. Specifically, it includes: Sequentially selecting 16 characters at preset positions based on the HASH result as the OTP result; Selecting 16 characters from the preset positions in the HASH result for combination and changing the combination order.
[0018] Optionally, the generation formula of the session key Skey is:
[0019] Skey = F(HASH(JOIN(T, S, K, RNG)))Skey = F(HASH(JOIN(T, S, K, RNG)));
[0020] The encryption and decryption processes adopt the CBC mode, and the encryption algorithms include but are not limited to SM4_cbc, AES_128_cbc, AES_192_cbc, AES_256_cbc; whether the data initiator is a drone or a ground station, the first data packet header contains a plaintext random number and the data encrypted by Skey. After receiving the first data, the receiver extracts the random number in the data header and generates an initial session key for decrypting the data.
[0021] The utility model has the following beneficial effects:
[0022] Enhanced data security: By combining national cryptographic algorithms (such as SM3 hashing algorithm and SM4 encryption algorithm) with OTP technology, high security during data transmission is ensured. National cryptographic algorithms are recognized by the country, with high security and anti-cracking capabilities, while OTP technology generates a unique session key for each data transmission, making each communication unique and greatly increasing the difficulty of data being stolen or tampered with.
[0023] Flexible key management mechanism: This solution generates the session key by combining the system time, the unique serial number of the encryption chip, true random numbers, and a preset encryption password, making the key generation both secure and flexible. At the same time, this mechanism also facilitates key update and management, enhancing the maintainability and scalability of the system.
[0024] Efficient data transmission efficiency: The generation process of the session key is fast and efficient, and it will not significantly affect the real-time performance of data transmission. At the same time, the encryption and decryption processes adopt the CBC mode, which can effectively protect the integrity and confidentiality of data while maintaining a high data transmission rate.
[0025] Easy to deploy and integrate: This solution establishes a secure data transmission channel among drones, relay drones, and ground stations without the need for large-scale transformation of existing hardware.
[0026] The technical solution of this patent effectively improves the security of UAV data transmission by adopting the national cryptographic algorithm and OTP (One-Time Password) technology. Data encryption ensures the confidentiality during the transmission process. The dynamically generated session key increases the timeliness and unpredictability of the key. Using the CBC mode for encryption further reduces the risk of the key being cracked. These measures prevent data from being eavesdropped, tampered with, and the control right from being seized, and are particularly suitable for application scenarios with high security requirements.
[0027] In terms of simplifying key management, the scheme uniformly configures the encryption key generation password (K) when the UAV leaves the factory, reducing the complexity of key management. The system automatically generates session keys without manual intervention, reducing the risk of human management. At the same time, the UAV and the ground station are paired by scanning codes, etc., which is easy to operate, reduces the configuration difficulty, and improves the user experience.
[0028] In addition, the scheme enhances the anti-attack ability of UAV data transmission. The multi-factor key generation process includes multiple dynamic factors, increasing the cracking difficulty through hashing and confusion algorithms. The plaintext random number included in the data packet header ensures the uniqueness of each data packet, improving the reliability and integrity of data transmission, and guaranteeing the security of UAV data transmission.
[0029] The information transmission distance is increased by using relay UAVs, making the information transmission distance farther. Originally, it was the transmission distance of one UAV, and now it is equivalent to the transmission distance of two UAVs. And the relay UAV can verify the instructions and encrypted information to ensure the accuracy and security of the information, intercepting inaccurate information, further increasing the security of UAV data transmission. Description of the Drawings
[0030] Figure 1 It is the logic block diagram of a UAV data encryption and secure transmission system of the present utility model;
[0031] Figure 2 It is the logic block diagram of the encryption management unit of a UAV data encryption and secure transmission system of the present utility model. Detailed Embodiments
[0032] Next, the technical solutions in the embodiments of the present utility model will be clearly and completely described in conjunction with the drawings in the embodiments of the present utility model. Obviously, the described embodiments are only a part of the embodiments of the present utility model, rather than all of the embodiments. Based on the embodiments of the present utility model, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present utility model.
[0033] In the description of the present utility model, it should be noted that the orientation or positional relationship indicated by the terms "center", "upper", "lower", "left", "right", "vertical", "horizontal", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings. It is only for the convenience of describing the present utility model and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation to the present utility model; the terms "first", "second", "third" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance. In addition, unless otherwise clearly specified and defined, the terms "installation", "connection", "connection" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present utility model can be understood according to specific circumstances.
[0034] Referring to Figure 1-2 As shown, the system includes an operation UAV, a relay UAV, and a ground station; the ground station includes a first wireless communication unit; the relay UAV includes a second wireless communication unit and an information confirmation unit; the operation UAV includes a UAV communication unit, a camera communication unit, and an encryption management unit;
[0035] The first wireless communication unit is electrically connected to the ground station and communicates with the second wireless communication unit;
[0036] The second wireless communication unit is electrically connected to the relay UAV, communicates with the UAV communication unit, receives flight status data and sends control commands from the ground station, also communicates with the camera communication unit, receives camera images and sends them to the ground station, and sends camera and gimbal control commands from the ground station;
[0037] The information confirmation unit is electrically connected to the second wireless communication unit, determines whether the received instructions from the ground station match, and determines whether the encryption information of the received operation UAV is complete; among them, determining whether the received instructions from the ground station match is to determine whether the instructions are sent by the corresponding ground station. If the instructions are not sent by the corresponding ground station, they are refused to be transmitted to the operation UAV, and a request for resending the instructions or confirming the sending of the instructions is sent to the corresponding ground station, where the corresponding ground station can be matched by means of a unique identification code, user information confirmation, password confirmation, etc. Among them, determining whether the encryption information of the received operation UAV is complete is to determine whether the operation of the operation UAV corresponds to the instructions, for example: whether the number of photos taken meets the requirements, whether the encrypted data of the executed instructions is lost / complete, whether the shooting target is correct, etc.
[0038] The UAV communication unit is electrically connected to the encryption management unit and communicates with the flight control unit of the operating UAV;
[0039] The camera communication unit is electrically connected to the encryption management unit and communicates with the camera of the operating UAV;
[0040] The encryption management unit is electrically connected to the operating UAV and is used for data encryption and decryption. It includes a session key generation unit. The encryption management unit also includes a national cryptography algorithm encryption chip, an OTP algorithm unit, and a data encryption / decryption session management module;
[0041] The session key generation unit establishes a temporary encryption key between the two communication parties to ensure the security of data transmission. The generated session key will be used for symmetric encryption of the transmitted data. It includes a JOIN algorithm module, a HASH algorithm module, and an F algorithm module.
[0042] Among them, the JOIN algorithm module is as follows: Obtain the system UNIX timestamp T1, the number of seconds calculated from January 1, 1970. Take the alignment result of 60, T = Treal−(Treal % 60), to obtain the time parameter T and convert it into the HEX character form; Generate a true random number RNG through the RNG unit in the encryption chip; Take the unique serial number S of the chip and the preset encryption password K; Concatenate T, RNG, S, and K in string form to form the JOIN result.
[0043] The HASH algorithm module performs a hashing operation using the SM3 algorithm to generate a HASH result. The HASH algorithm module selects SHA192, SHA256, SM3.
[0044] The F algorithm module performs calculations, splitting, and recombination on the HASH result to generate a session key Skey that meets the length of the encryption algorithm. Specifically, it includes: Sequentially select 16 characters at preset positions based on the HASH result as the OTP result; Select 16 characters from the preset positions in the HASH result for combination and change the combination order.
[0045] The generation formula of the session key Skey is:
[0046] Skey = F(HASH(JOIN(T, S, K, RNG)))Skey = F(HASH(JOIN(T, S, K, RNG)));
[0047] The encryption and decryption process adopts the CBC mode. The encryption algorithms include but are not limited to SM4_cbc, AES_128_cbc, AES_192_cbc, AES_256_cbc;
[0048] Whether the data originator is a drone or a ground station, the first data packet header contains a plaintext random number and the data encrypted by Skey. After receiving the first data, the receiver extracts the random number in the data header and generates an initial session key for decrypting the data.
[0049] The session key generation unit includes the following steps:
[0050] S1. Obtain the system UNIX timestamp T1, subtract the result of modulo 60 to get the time parameter T, and convert it into the HEX character form;
[0051] S2. Generate a true random number RNG through the RNG unit in the encryption chip;
[0052] S3. Obtain the unique serial number S of the chip and the preset encryption password K;
[0053] S4. Concatenate (JOIN) T, RNG, S, and K in string form to form a concatenated string;
[0054] S5. Use the SM3 algorithm to perform a hashing operation (HASH) on the concatenated string;
[0055] S6. Perform calculations, splitting, and recombination (F) on the hashing result to generate a session key Skey that meets the length of the encryption algorithm.
[0056] As a further description of the above technical solution:
[0057] The method includes the following steps:
[0058] Step 1: When the drone leaves the factory, write the unified encryption key generation password K into the secure storage area of the national cryptography chip and record the encryption chip serial number S;
[0059] Step 2: Save the same encryption key generation password K at the ground station;
[0060] Step 3: When the drone and the ground station are paired, import and save the serial number S by scanning the code or other means;
[0061] Step 4: When the drone or the ground station initiates the initial data, the OTP algorithm unit generates a session key, which is generated by the standard clock T, the unique serial number S of the encryption chip, the true random number RNG generated by the encryption chip, and the preset encryption key generation password K at the time of leaving the factory;
[0062] Step 5: The data originator includes a plaintext random number and the data encrypted by the session key in the first data packet header;
[0063] Step 6: After receiving the data, the receiver extracts the random number in the data header and generates an initial session key for decrypting the data.
[0064] As a further description of the above technical solution:
[0065] The JOIN algorithm module is as follows:
[0066] Obtain the system UNIX timestamp T1, the number of seconds calculated from January 1, 1970, and take the alignment result of 60, T = Treal−(Treal % 60), to obtain the time parameter T and convert it into the form of HEX characters;
[0067] Generate a true random number RNG through the RNG unit in the encryption chip;
[0068] Obtain the unique serial number S of the chip and the preset encryption password K;
[0069] Concatenate T, RNG, S, and K in string form to form the JOIN result.
[0070] As a further description of the above technical solution:
[0071] The HASH algorithm module performs a hashing operation using the SM3 algorithm to generate a HASH result. The HASH algorithm module selects SHA192, SHA256, or SM3.
[0072] As a further description of the above technical solution:
[0073] The F algorithm module performs calculations, splitting, and recombination on the HASH result to generate a session key Skey that meets the length of the encryption algorithm, specifically including:
[0074] Sequentially select 16 characters at preset positions based on the HASH result as the OTP result;
[0075] Select 16 characters from the preset positions based on the HASH result for combination and change the combination order.
[0076] As a further description of the above technical solution:
[0077] The generation formula of the session key Skey is:
[0078] Skey = F(HASH(JOIN(T, S, K, RNG)))Skey = F(HASH(JOIN(T, S, K, RNG)));
[0079] The encryption and decryption processes use the CBC mode, and the encryption algorithms include but are not limited to SM4_cbc, AES_128_cbc, AES_192_cbc, and AES_256_cbc;
[0080] Whether the data initiator is a drone or a ground station, the first data packet header contains a plaintext random number and data encrypted by Skey. After receiving the first data, the receiver extracts the random number in the data header and generates an initial session key for decrypting the data.
[0081] As a further description of the above technical solution:
[0082] The encryption management unit realizes data encryption and decryption through the following steps:
[0083] Step 1: When the drone or the ground station initiates the initial data, the OTP algorithm unit generates a session key;
[0084] Step 2: Use the session key to encrypt the data. The data initiator includes a plaintext random number in the first data packet header;
[0085] Step 3: The data receiver extracts the random number in the data header and generates the same session key as the initiator;
[0086] Step 4: Use the session key to decrypt the data.
[0087] Operation process:
[0088] The ground station sends an operation instruction to the second wireless communication unit of the relay drone through the first wireless communication unit. After the instruction is confirmed by the information confirmation unit to be sent by the corresponding ground station, the operation instruction is sent to the drone communication unit and the camera communication unit of the operation drone through the second wireless communication unit. The drone communication unit instructs the flight control unit to complete the flight task, and the camera communication unit instructs the camera unit to complete the shooting task. After the task is completed, the encryption management unit encrypts the data, and the drone communication unit and the camera communication unit transmit their respective data to the second wireless communication unit. After the encrypted data is confirmed by the information confirmation unit to be complete task data, the encrypted data is sent to the ground station through the second wireless communication unit.
[0089] Finally, it should be noted that the above are only the preferred embodiments of the present invention and are not used to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A drone data encryption and secure transmission system, characterized by: It includes an operating drone, a relay drone, and a ground station; the ground station includes a first wireless communication unit; the relay drone includes a second wireless communication unit and an information confirmation unit; the operating drone includes a drone communication unit, a camera communication unit, and an encryption management unit; The first wireless communication unit is electrically connected to the ground station and communicates with the second wireless communication unit; The second wireless communication unit is electrically connected to the relay drone, communicates with the drone communication unit, receives flight status data and sends control commands from the ground station, and also communicates with the camera communication unit, receives camera images and sends them to the ground station, and sends camera and gimbal control commands from the ground station; The information confirmation unit is electrically connected to the second wireless communication unit to determine whether the received command from the ground station matches, and to determine whether the received encrypted information of the operating drone is complete; The UAV communication unit is electrically connected to the encryption management unit and communicates with the flight control unit of the operating UAV; The camera communication unit is electrically connected to the encryption management unit and communicates with the camera of the operating drone; The encryption management unit is electrically connected to the operating drone and is used for data encryption and decryption, including a session key generation unit. The encryption management unit also includes a national secret algorithm encryption chip, an OTP algorithm unit, and a data encryption and decryption session management module; The session key generation unit establishes a temporary encryption key between the communicating parties to ensure the security of data transmission. The generated session key will be used to symmetrically encrypt the transmitted data, which includes a JOIN algorithm module, a HASH algorithm module and an F algorithm module.
2. The UAV data encryption and secure transmission system according to claim 1 is characterized by: The JOIN algorithm module is: Take the system UNIX timestamp T1, the number of seconds calculated from January 1, 1970, take the alignment result T=Treal−(Treal % 60) of 60, obtain the time parameter T, and convert it into HEX character form; Generate true random number RNG through the RNG unit in the encryption chip; Get the chip's unique serial number S and the preset encryption password K; Concatenate T, RNG, S, and K in string form to form a JOIN result.
3. The UAV data encryption and secure transmission system according to claim 2 is characterized by: The HASH algorithm module uses the SM3 algorithm to perform hash operations and generate HASH results. The HASH algorithm module selects SHA192, SHA256, and SM3.
4. The UAV data encryption and secure transmission system according to claim 2 is characterized by: The F algorithm module calculates, splits, and reorganizes the HASH result to generate a session key Skey that meets the encryption algorithm length, specifically including: Based on the HASH result, 16 characters are sequentially selected at the preset positions as the OTP result; Based on the HASH result, 16 characters are selected from the preset positions for combination and the combination order is changed.
5. The UAV data encryption and secure transmission system according to claim 4 is characterized by: The generation formula of the session key Skey is: Skey=F(HASH(JOIN(T,S,K,RNG)))Skey=F(HASH(JOIN(T,S,K,RNG))); The encryption and decryption process adopts CBC mode, and the encryption algorithms include but are not limited to SM4_cbc, AES_128_cbc, AES_192_cbc, and AES_256_cbc; Whether the data initiator is a drone or a ground station, the first data packet header contains a plaintext random number and data encrypted by Skey. After the receiver receives the first data, it extracts the random number in the data header and generates an initial session key for decrypting the data.